Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.4
CVE-2014-2269EPSS 16%
modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a reques…
Vtiger Crm
Patch available
HIGH 7.5
CVE-2013-3213
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklis…
Vtiger Crm
No fix yet
MEDIUM 6.5
CVE-2013-5091
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL…
Vtiger Crm
after 5.4.0
MEDIUM 5.0
CVE-2012-4867
Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary fil…
Vtiger Crm
No fix yet
HIGH 7.5
CVE-2011-4559
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the …
Vtiger Crm
after 5.2.1
MEDIUM 6.8
CVE-2010-3910EPSS 7%
Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow …
Vtiger Crm
after 5.2.0
MEDIUM 6.0
CVE-2010-3909
Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by u…
Vtiger Crm
after 5.2.0
HIGH 9.0
CVE-2009-3258
vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie…
Vtiger Crm
Mitigation only
HIGH 9.0
CVE-2009-3250EPSS 11%
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary cod…
Vtiger Crm
No fix yet
HIGH 7.5
CVE-2009-3249EPSS 10%
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot do…
Vtiger Crm
No fix yet
MEDIUM 6.8
CVE-2009-3248
Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u…
Vtiger Crm
No fix yet
MEDIUM 5.0
CVE-2008-3458
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail …
Vtiger Crm
after 5.0.3
HIGH 8.5
CVE-2007-3599
vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permis…
Vtiger Crm
after 5.0.2
MEDIUM 6.5
CVE-2007-3603
SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute …
Vtiger Crm
after 5.0.2
MEDIUM 6.5
CVE-2007-3616
index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain …
Vtiger Crm
after 5.0.2
MEDIUM 5.5
CVE-2007-3598
index.php in vtiger CRM before 5.0.3 allows remote authenticated users to obtain all users' names and e-mail addresses, and possibly change user sett…
Vtiger Crm
after 5.0.2
MEDIUM 5.5
CVE-2007-3602
The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with i…
Vtiger Crm
after 5.0.2
HIGH 7.5
CVE-2006-5289EPSS 8%
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th…
Vtiger Crm
No fix yet
HIGH 7.5
CVE-2006-4617
Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and e…
Vtiger Crm
after 4.2.4
HIGH 7.5
CVE-2006-4588
vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to in…
Vtiger Crm
No fix yet
MEDIUM 6.8
CVE-2006-4587
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script …
Vtiger Crm
Mitigation only
HIGH 7.5
CVE-2005-3819
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authenticatio…
Vtiger Crm
after 4.2
HIGH 7.5
CVE-2005-3822
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in…
Vtiger Crm
after 4.2
HIGH 7.5
CVE-2005-3823
The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parame…
Vtiger Crm
after 4.2
MEDIUM 6.4
CVE-2005-3820
Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an…
Vtiger Crm
after 4.2
MEDIUM 5.0
CVE-2005-3824
The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.
Vtiger Crm
after 4.2